<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD Computer not recognized in Access Roles with Machine Authentication in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Computer-not-recognized-in-Access-Roles-with-Machine/m-p/128132#M8136</link>
    <description>&lt;P&gt;Is Remote Access configured as an identity source in your gateway object?&lt;BR /&gt;Also, it's possible the machine identity would need to come from your AD server in this case...I presume your client can reach the AD server(s) when connected via VPN?&lt;/P&gt;</description>
    <pubDate>Thu, 26 Aug 2021 15:05:35 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-08-26T15:05:35Z</dc:date>
    <item>
      <title>AD Computer not recognized in Access Roles with Machine Authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Computer-not-recognized-in-Access-Roles-with-Machine/m-p/127859#M8135</link>
      <description>&lt;P&gt;We have implemented machine authentication successfully on R80.40. I see the machine authenticating and the value of the Subject field in the certificate appears in the log. However, i am unable to use Access Roles that test for specific machines/groups from the Active Directory. Even though the machine is recognized, the Access Role is not matched. I have tried populating the certificate with the plain CN as well as the full DN. Nothing seems to work. I can create an access role with "All identified machines", but not with specific machines or groups. Has anyone implemented this successfully?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Moshe&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 14:12:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Computer-not-recognized-in-Access-Roles-with-Machine/m-p/127859#M8135</guid>
      <dc:creator>mlinzer</dc:creator>
      <dc:date>2021-08-24T14:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: AD Computer not recognized in Access Roles with Machine Authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Computer-not-recognized-in-Access-Roles-with-Machine/m-p/128132#M8136</link>
      <description>&lt;P&gt;Is Remote Access configured as an identity source in your gateway object?&lt;BR /&gt;Also, it's possible the machine identity would need to come from your AD server in this case...I presume your client can reach the AD server(s) when connected via VPN?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 15:05:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Computer-not-recognized-in-Access-Roles-with-Machine/m-p/128132#M8136</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-26T15:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: AD Computer not recognized in Access Roles with Machine Authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Computer-not-recognized-in-Access-Roles-with-Machine/m-p/128210#M8137</link>
      <description>&lt;P&gt;Yes, remote access is configured under Identity Sources. The clients can access the AD server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Users and user groups are identified fine. The problem is with machine identity.&lt;/P&gt;&lt;P&gt;What is the recommended value for the Subject field in the Machine Certificate?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 08:14:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Computer-not-recognized-in-Access-Roles-with-Machine/m-p/128210#M8137</guid>
      <dc:creator>mlinzer</dc:creator>
      <dc:date>2021-08-27T08:14:48Z</dc:date>
    </item>
  </channel>
</rss>

